This is a read-only archive of malwareremoval.com. No new posts or registrations. Privacy Page
Malware Removal Forums

funbangladesh

45 min read

This thread's last reply is from January 1, 2006, 9:29 AM UTC. Software, malware, and removal-tool advice below may be out of date — treat specific steps and download links with caution.

HI,
I scanned my Pc with Kaspersky on line and look what was found:

-------------------------------------------------------------------------------
KASPERSKY ON-LINE SCANNER REPORT
Wednesday, December 28, 2005 16:01:01
Operating System: Microsoft Windows XP Professional, (Build 2600)
Kaspersky On-line Scanner version: 5.0.67.0
Kaspersky Anti-Virus database last update: 28/12/2005
Kaspersky Anti-Virus database records: 167975
-------------------------------------------------------------------------------

Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true

Scan Target - My Computer:
A:\
C:\
D:\
E:\
F:\

Scan Statistics:
Total number of scanned objects: 31435
Number of viruses found: 4
Number of infected objects: 6
Number of suspicious objects: 0
Duration of the scan process: 4799 sec

Infected Object Name - Virus Name
C:\System Volume Information\_restore{B22D9EFC-8B1D-4299-88D0-76C4229F0FFA}\RP42\A0010200.exe/a Infected: Net-Worm.Win32.Randon.aa
C:\System Volume Information\_restore{B22D9EFC-8B1D-4299-88D0-76C4229F0FFA}\RP42\A0010200.exe/b Infected: Net-Worm.Win32.Randon.aa
C:\System Volume Information\_restore{B22D9EFC-8B1D-4299-88D0-76C4229F0FFA}\RP42\A0010200.exe/dlcl.edp Infected: Backdoor.IRC.Zapchast
C:\System Volume Information\_restore{B22D9EFC-8B1D-4299-88D0-76C4229F0FFA}\RP42\A0010200.exe/hosts Infected: Trojan.Win32.Qhost
C:\System Volume Information\_restore{B22D9EFC-8B1D-4299-88D0-76C4229F0FFA}\RP42\A0010200.exe Infected: Trojan.Win32.Qhost
C:\WINDOWS\system32\client.exe Infected: Backdoor.Win32.VB.ann

Scan process completed.

Shall I delete those files??? It seems that this is going to go on for ever. Don't you think??
C:\System Volume Information\_restore{B22D9EFC-8B1D-4299-88D0-76C4229F0FFA}\RP42\A0010200.exe/a Infected: Net-Worm.Win32.Randon.aa
C:\System Volume Information\_restore{B22D9EFC-8B1D-4299-88D0-76C4229F0FFA}\RP42\A0010200.exe/b Infected: Net-Worm.Win32.Randon.aa
C:\System Volume Information\_restore{B22D9EFC-8B1D-4299-88D0-76C4229F0FFA}\RP42\A0010200.exe/dlcl.edp Infected: Backdoor.IRC.Zapchast
C:\System Volume Information\_restore{B22D9EFC-8B1D-4299-88D0-76C4229F0FFA}\RP42\A0010200.exe/hosts Infected: Trojan.Win32.Qhost
C:\System Volume Information\_restore{B22D9EFC-8B1D-4299-88D0-76C4229F0FFA}\RP42\A0010200.exe Infected: Trojan.Win32.Qhost

In a previous post (Preventative measures) dated Dec 01/2005 9:56AM one of the issues was a follows:
c:\System Volume Information\_restore….

ONCE your are as clean as possible - As a final cleanup step, it is often advisable to Reset and Re-enable your System Restore to remove any bad files that may have been backed up by Windows . The files in System Restore are protected to prevent any programs changing them. And, this is the only complete way to clean these files: (You will lose all previous restore points which could likely be infected, anyway.)

PLEASE NOTE: you will need to log into your computer with an account that has full administrator access. You will know if the account has administrator access because you will be able to see the System Restore tab. If the tab is missing, you are logged in under a limited account.

(Windows XP)
To Turn OFF System Restore.
  1. Click the Start button.
  2. Right-click My Computer, and then click Properties.
  3. On the System Restore tab, check Turn off System Restore or Turn off System Restore on all drives.
  4. Click Apply.


To Turn ON System Restore.
  1. Follow the steps in the previous section, but in step 3, uncheck Turn off System Restore or Turn off System Restore on all drives. Then click OK.
  2. Create new System Restore points.




Delete the following file, in SAFE MODE if necessary:
C:\WINDOWS\system32\client.exe
Thanks for the speedy answer; by return of post.
Glad we could be of assistance.

As this issue appears to be resolved, this topic is now closed. If you wish it reopened, please send us an email to 'admin at malwareremoval.com' with a link to your thread.

You can help support this site from this link :
Donations For Malware Removal

Do not bother contacting us if you are not the topic starter. A valid, working link to the closed topic is required along with the user name used. If the user name does not match the one in the thread linked, the email will be deleted.